Red Hat organization management: system information exposure
Medium4.9CVE-2026-16072 · Published Jul 17, 2026 · updated Sep 16, 2026
A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Data Grid 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.6.7 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 17 | Red Hat xdgmime: heap buffer overflow | High7.1 | No fix yet |
| Jul 17 | Red Hat Data Grid 8: untrusted input in a security decision | Medium5.4 | No fix yet |
| Jul 17 | Red Hat keycloak-services: attacker could obtain access | Medium4.3 | No fix yet |
| Jul 17 | Red Hat Data Grid 8: weakly protected credentials | Medium4.3 | No fix yet |
| Jul 17 | Red Hat admin REST API of Keycloak: missing authorization | Medium4.9 | No fix yet |
| Jul 17 | Red Hat default-groups REST endpoint: information disclosure | Medium4.3 | No fix yet |